# Is FileBeat Alive?

**URL:** https://discuss.elastic.co/t/is-filebeat-alive/49121
**Category:** Beats
**Tags:** filebeat
**Created:** [May 4, 2016, 4:00am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121 "2016-05-04T04:00:27Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 4, 2016, 4:00am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/1 "2016-05-04T04:00:28Z")

</div>

Hi,

I am having Filebeat running on Windows Servers Reading many log files on each server.  
The data is being sent to RHEL Servers running the Logstash and Elasticsearch.

I would like to have a way in which I will be able to know from the RHEL Servers if the Filebeat is Alive and there is no problem with the Service (While there are no logs being written).

What can be best way doing it ?

Thanks,

Ori

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 4, 2016, 4:13am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/2 "2016-05-04T04:13:01Z")

</div>

Topbeat should be able to do that - [https://www.elastic.co/guide/en/beats/topbeat/current/topbeat-configuration.html](https://www.elastic.co/guide/en/beats/topbeat/current/topbeat-configuration.html)

---

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 4, 2016, 4:40am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/3 "2016-05-04T04:40:23Z")

</div>

Thanks,

What will be generated if I am running Topbeat for the Filebeat process, but the filebeat is not running ?  
Will it generate a line with 0 CPU, 0 Memory, No ProcessID, Or nothing will be generated ?

I would prefer something that can be generated using the Filebeat itself and not to use another utility.

Ori

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 4, 2016, 4:45am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/4 "2016-05-04T04:45:04Z")

</div>

> [@ori.rubinfeld](#):
>
> I would prefer something that can be generated using the Filebeat itself and not to use another utility.

I don't think you can monitor Filebeat with itself, that's a circular dependancy.

---

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 4, 2016, 4:48am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/5 "2016-05-04T04:48:25Z")

</div>

We have a monitor for the Service to check if it is running or not.  
I would also like to know, If it is running and data is not being send to the Logstash.

Ori

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [May 4, 2016, 5:15am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/6 "2016-05-04T05:15:13Z")

</div>

> I don't think you can monitor Filebeat with itself, that's a circular dependancy.

True, but Filebeat (and all other beats) could have an optional HTTP endpoint for status and stats information.

---

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 4, 2016, 5:16am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/7 "2016-05-04T05:16:32Z")

</div>

How can I access it ?

Thanks,

Ori

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [May 4, 2016, 5:17am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/8 "2016-05-04T05:17:36Z")

</div>

I said that they _could_ have an HTTP endpoint. AFAIK there's no such thing right now.

---

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 4, 2016, 11:09am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/9 "2016-05-04T11:09:45Z")

</div>

What is purpose of the flag: -httpprof  
While running the Filebeat ?  
How can I use it ?

When setting a hostname and port, it gives nothing.

Ori

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [May 4, 2016, 11:14am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/10 "2016-05-04T11:14:09Z")

</div>

It's the Golang's pprof interface: [https://golang.org/pkg/net/http/pprof/](https://golang.org/pkg/net/http/pprof/)

Try the `/debug/vars` endpoint, it prints some metrics from libbeat which could be use as some sort of status information.

---

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 4, 2016, 11:19am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/11 "2016-05-04T11:19:11Z")

</div>

Great!!!!

Can I use the first Variables for monitoring activity:

{  
"cmdline": ["filebeat.exe","-httpprof","127.0.0.1:8080"],  
**"libbeatEsPublishEventsCallCount": 0,**  
**"libbeatEsPublishedAndAckedEvents": 0,**  
**"libbeatEsPublishedButNotAckedEvents": 0,**  
**"libbeatLogstashPublishEventsCallCount": 0,**  
**"libbeatLogstashPublishedAndAckedEvents": 0,**  
**"libbeatLogstashPublishedButNotAckedEvents": 0,**  
**"libbeatMessagesDropped": 0,**  
**"libbeatMessagesInWorkerQueues": 0,**  
**"libbeatPublishedEvents": 0,**  
"memstats": {"Alloc":2311672,"TotalAlloc":2311672,"Sys":5442684,"Lookups":45,"Mallocs":23414,"Frees":0,"HeapAlloc":2311672,"HeapSys":2949120,"HeapIdle":122880,"HeapInuse":2826240,"HeapReleased":0,"HeapObjects":23414,"StackInuse":196608,"StackSys":196608,"MSpanInuse":19108,"MSpanSys":32768,"MCacheInuse":2384,"MCacheSys":16384,"BuckHashSys":726380,"GCSys":196608,"OtherSys":1324816,"NextGC":4194304,"LastGC":0,"PauseTotalNs":0,"PauseNs":[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"PauseEnd":[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"NumGC":0,"GCCPUFraction":0,"EnableGC":true,"DebugGC":false,"BySize":[{"Size":0,"Mallocs":0,"Frees":0},{"Size":8,"Mallocs":1533,"Frees":0},{"Size":16,"Mallocs":6435,"Frees":0},{"Size":32,"Mallocs":2561,"Frees":0},{"Size":48,"Mallocs":7231,"Frees":0},{"Size":64,"Mallocs":638,"Frees":0},{"Size":80,"Mallocs":1287,"Frees":0},{"Size":96,"Mallocs":1306,"Frees":0},{"Size":112,"Mallocs":367,"Frees":0},{"Size":128,"Mallocs":85,"Frees":0},{"Size":144,"Mallocs":118,"Frees":0},{"Size":160,"Mallocs":78,"Frees":0},{"Size":176,"Mallocs":181,"Frees":0},{"Size":192,"Mallocs":1027,"Frees":0},{"Size":208,"Mallocs":26,"Frees":0},{"Size":224,"Mallocs":57,"Frees":0},{"Size":240,"Mallocs":2,"Frees":0},{"Size":256,"Mallocs":19,"Frees":0},{"Size":288,"Mallocs":46,"Frees":0},{"Size":320,"Mallocs":16,"Frees":0},{"Size":352,"Mallocs":13,"Frees":0},{"Size":384,"Mallocs":4,"Frees":0},{"Size":416,"Mallocs":5,"Frees":0},{"Size":448,"Mallocs":5,"Frees":0},{"Size":480,"Mallocs":2,"Frees":0},{"Size":512,"Mallocs":6,"Frees":0},{"Size":576,"Mallocs":43,"Frees":0},{"Size":640,"Mallocs":23,"Frees":0},{"Size":704,"Mallocs":11,"Frees":0},{"Size":768,"Mallocs":4,"Frees":0},{"Size":896,"Mallocs":23,"Frees":0},{"Size":1024,"Mallocs":3,"Frees":0},{"Size":1152,"Mallocs":37,"Frees":0},{"Size":1280,"Mallocs":4,"Frees":0},{"Size":1408,"Mallocs":3,"Frees":0},{"Size":1536,"Mallocs":3,"Frees":0},{"Size":1664,"Mallocs":5,"Frees":0},{"Size":2048,"Mallocs":6,"Frees":0},{"Size":2304,"Mallocs":34,"Frees":0},{"Size":2560,"Mallocs":5,"Frees":0},{"Size":2816,"Mallocs":2,"Frees":0},{"Size":3072,"Mallocs":4,"Frees":0},{"Size":3328,"Mallocs":1,"Frees":0},{"Size":4096,"Mallocs":77,"Frees":0},{"Size":4608,"Mallocs":33,"Frees":0},{"Size":5376,"Mallocs":4,"Frees":0},{"Size":6144,"Mallocs":33,"Frees":0},{"Size":6400,"Mallocs":0,"Frees":0},{"Size":6656,"Mallocs":0,"Frees":0},{"Size":6912,"Mallocs":1,"Frees":0},{"Size":8192,"Mallocs":1,"Frees":0},{"Size":8448,"Mallocs":0,"Frees":0},{"Size":8704,"Mallocs":0,"Frees":0},{"Size":9472,"Mallocs":0,"Frees":0},{"Size":10496,"Mallocs":0,"Frees":0},{"Size":12288,"Mallocs":0,"Frees":0},{"Size":13568,"Mallocs":0,"Frees":0},{"Size":14080,"Mallocs":1,"Frees":0},{"Size":16384,"Mallocs":2,"Frees":0},{"Size":16640,"Mallocs":0,"Frees":0},{"Size":17664,"Mallocs":0,"Frees":0}]}  
}

Ori

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [May 4, 2016, 11:23am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/12 "2016-05-04T11:23:21Z")

</div>

Yeah, just keep in mind that we intentionally didn't document this because the variable names and such might change.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [May 4, 2016, 2:48pm UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/13 "2016-05-04T14:48:28Z")

</div>

there is even a community beat collecting these variables from `-httpprof`: [https://github.com/urso/govarbeat](https://github.com/urso/govarbeat)

---

<div class="post-metadata">

### Author: ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)
#### Post date: [May 9, 2016, 8:31am UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/14 "2016-05-09T08:31:16Z")

</div>

I think implementing it as follows:

Upgrade to Version 1.2+ of Filebeat, having the CLOSE\_OLDER parameter.

Then configure a prospector to run against my pre-defined folder having a file to be changed every 5 minutes.  
set:  
IGNORE\_OLDER=3m  
CLOSE\_OLDER=1m

I will be able to delete the file and create a new one with an updated TIMESTAMP.  
keeping the file size small.  
Then the filebeat will send the data to Logstash and from there to ElasticSearch to a Pre-defined index.  
By querying that index I will be able to know if the data keeps coming from the filebeat or not.

Ori

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/is-filebeat-alive/49121/15 "2017-07-05T21:52:16Z")

</div>


